MidnightBSD

Advisories for jacic

CVE-2022-41993

Cross-site scripting vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.

Products Affected

Vendor Product Version
jacic electronic_bidding_core_system *
jacic electronic_bidding_core_system 6
CVE-2022-46287

Cross-site scripting vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.

Products Affected

Vendor Product Version
jacic electronic_bidding_core_system *
jacic electronic_bidding_core_system 6
CVE-2022-46288

Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

Products Affected

Vendor Product Version
jacic electronic_bidding_core_system *
jacic electronic_bidding_core_system 6